CVE-2022-45406
NixOS vulnerability analysis and mitigation

Overview

CVE-2022-45406 is a high-impact use-after-free vulnerability discovered in Mozilla Firefox's JavaScript engine. The vulnerability was reported by Samuel Groß and fixed in Firefox 107, Firefox ESR 102.5, and Thunderbird 102.5, released on November 15, 2022. The vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107 (Mozilla Advisory, CVE Details).

Technical details

The vulnerability occurs when an out-of-memory condition happens during the creation of a JavaScript global object. In this scenario, a JavaScript realm may be deleted while references to it still exist in a BaseShape. This condition leads to a use-after-free situation that could potentially result in an exploitable crash. The issue was particularly related to the garbage collection process and memory management in Firefox's JavaScript engine (Mozilla Advisory).

Impact

The vulnerability is rated as high impact. When successfully exploited, it could lead to a potentially exploitable crash of the browser, which might allow for arbitrary code execution. The vulnerability affects multiple Mozilla products including Firefox, Firefox ESR, and Thunderbird, making it a significant security concern (Mozilla Advisory).

Exploitability

The vulnerability requires specific conditions to be exploited, particularly an out-of-memory condition during JavaScript global object creation. According to security researchers, the exploit is considered difficult to construct, requiring precise timing and specific conditions to trigger the vulnerability (Mozilla Bug).

Mitigation and workarounds

The vulnerability has been fixed in Firefox 107, Firefox ESR 102.5, and Thunderbird 102.5. Users are advised to update their Mozilla products to these versions or newer to mitigate the risk. The fix involves modifying the lifetime management of realms to prevent them from being swept when allocated during incremental garbage collection (Mozilla Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management